I built my compliance tool to fail the build, and I did it on purpose. Most audit-evidence tooling has one job: make the report look complete. Mine does the opposite.

Opencomplai's Annex IV dossier generator (opencomplai docs generate) builds the package you would hand an auditor. System description. Risk classification. Evidence attachments.

Every field in that dossier comes from exactly one of three places: something automated from your manifest and risk classification, real evidence wired in from an actual scan or eval report, or an explicit placeholder that says a human hasn't provided this yet.

There is no fourth place. The generator never fills a gap with boilerplate so the PDF looks finished.

Here's the part that costs me adoption. If your system is classified HIGH-risk and the dossier still has a placeholder in a required field, the release gate fails.

Not flags. Fails. The tool that is supposed to prove you are compliant will block your deploy rather than hand you a complete-looking dossier that isn't.

I know what that does to my numbers. A tool that gates your release on missing evidence is a harder sell than one that always prints a green checkmark. It's not a great pitch. I decided I could live with that.

I spent fourteen years watching systems fail. The ones that failed worst were the ones whose reports said everything was fine. A compliance report that can't tell "we checked" from "we didn't get around to it" isn't worth generating.

If you've used GRC tooling that treats "the field has text in it" as "the control is satisfied", compare it against how this release gate actually reads dossier state before it decides pass or fail. It isn't behind a paywall, it's in services/doc-generator: github.com/Opencomplai/opencomplai.